CVE-2026-53255 is a vulnerability in Linux Kernel
Published on June 25, 2026
Bluetooth: MGMT: validate advertising TLV before type checks
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: MGMT: validate advertising TLV before type checks
tlv_data_is_valid() reads each advertising data field length from
data[i], then inspects data[i + 1] for managed EIR types before
checking that the current field still fits inside the supplied buffer.
A malformed field whose length byte is the last byte of the buffer can
therefore make the parser read one byte past the advertising data.
KASAN reported the following when a malformed MGMT_OP_ADD_ADVERTISING
request reached that path:
BUG: KASAN: vmalloc-out-of-bounds in tlv_data_is_valid()
Read of size 1
Call trace:
tlv_data_is_valid()
add_advertising()
hci_mgmt_cmd()
hci_sock_sendmsg()
Move the existing element-length check before any type-octet inspection
so each non-empty element is proven to contain its type byte before the
parser looks at data[i + 1].
Products Associated with CVE-2026-53255
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 2bb36870e8cb29949ef9acec37129cd8e70f1857 and below 13ad995071a06570668dd8daab3616c247c72080 is affected.
- Version 2bb36870e8cb29949ef9acec37129cd8e70f1857 and below 06fcbd79c3c360a50f9be9d370769bbd738d0976 is affected.
- Version 2bb36870e8cb29949ef9acec37129cd8e70f1857 and below f7093ac233c1e7f51d125534f46067772a113175 is affected.
- Version 2bb36870e8cb29949ef9acec37129cd8e70f1857 and below 74c08e4db35a476c3462aeb65846f955be732626 is affected.
- Version 2bb36870e8cb29949ef9acec37129cd8e70f1857 and below 18fea1cb0c2599752e908c8217490f73ddd33e00 is affected.
- Version 2bb36870e8cb29949ef9acec37129cd8e70f1857 and below 1a3c8ffbb469859b076445af44bdfa6a711d483e is affected.
- Version 2bb36870e8cb29949ef9acec37129cd8e70f1857 and below 2a3f3ed9e198ae23c15859ace2f9ca6cfdc35b57 is affected.
- Version 2bb36870e8cb29949ef9acec37129cd8e70f1857 and below de23fb62259aa01d294f77238ae3b835eb674413 is affected.
- Version 4.9 is affected.
- Before 4.9 is unaffected.
- Version 5.10.259, <= 5.10.* is unaffected.
- Version 5.15.210, <= 5.15.* is unaffected.
- Version 6.1.176, <= 6.1.* is unaffected.
- Version 6.6.143, <= 6.6.* is unaffected.
- Version 6.12.94, <= 6.12.* is unaffected.
- Version 6.18.36, <= 6.18.* is unaffected.
- Version 7.0.13, <= 7.0.* is unaffected.
- Version 7.1, <= * is unaffected.